Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 572 respecto a la semana anterior
Críticas / altas1301▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)295▼ 215 respecto a la semana anterior
132 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 0.36% | — | Supsystic Popup | 15/4/2024 | 17/6/2026 | Missing Authorization vulnerability in supsystic Popup by Supsystic popup-by-supsystic.This issue affects Popup by Supsystic: from n/a through <= 1.10.27. | |
| Aplazada | Media (4.3) | 0.21% | — | Supsystic Digital PublicationsAI | 15/4/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Supsystic Digital Publications by Supsystic.This issue affects Digital Publications by Supsystic: from n/a through 1.7.7. | |
| Aplazada | Media (4.3) | 0.20% | — | Supsystic Ultimate MapsAI | 12/4/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Supsystic Ultimate Maps by Supsystic.This issue affects Ultimate Maps by Supsystic: from n/a through 1.2.16. | |
| Modificada | Alta (8.8) | 0.23% | — | Supsystic Easy Google Maps | 12/4/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Supsystic Easy Google Maps.This issue affects Easy Google Maps: from n/a through 1.11.11. | |
| Aplazada | Media (5.9) | 0.36% | — | Supsystic SliderAI | 29/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Supsystic Slider by Supsystic allows Stored XSS.This issue affects Slider by Supsystic: from n/a through 1.8.10. | |
| Aplazada | Alta (7.6) | 0.55% | — | Slider BY SupsysticAI | 28/3/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Supsystic Slider by Supsystic.This issue affects Slider by Supsystic: from n/a through 1.8.10. | |
| Modificada | Media (4.8) | 0.34% | — | Supsystic Photo Gallery | 27/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in supsystic Photo Gallery by Supsystic gallery-by-supsystic.This issue affects Photo Gallery by Supsystic: from n/a through <= 1.15.16. | |
| Modificada | Media (4.8) | 0.42% | — | Supsystic Ultimate Maps | 16/1/2024 | 17/6/2026 | The Ultimate Maps by Supsystic WordPress plugin before 1.2.16 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed | |
| Modificada | Media (5.4) | 0.29% | — | Synopsys Seeker | 9/1/2024 | 17/6/2026 | Synopsys Seeker versions prior to 2023.12.0 are vulnerable to a stored cross-site scripting vulnerability through a specially crafted payload. | |
| Modificada | Media (6.5) | 0.52% | — | Phpsysinfo | 19/12/2023 | 17/6/2026 | Cross Site Request Forgery (CSRF) vulnerability in Phpsysinfo version 3.4.3 allows a remote attacker to obtain sensitive information via a crafted page in the XML.php file. | |
| Modificada | Media (4.8) | 0.39% | — | Supsystic Gdpr Cookie Consent | 15/12/2023 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Supsystic GDPR Cookie Consent by Supsystic allows Stored XSS.This issue affects GDPR Cookie Consent by Supsystic: from n/a through 2.1.2. | |
| Modificada | Alta (8.8) | 0.27% | — | Digital Publications BY Supsystic | 9/12/2023 | 17/6/2026 | The Digital Publications by Supsystic plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.7.6. This is due to missing or incorrect nonce validation on the AJAX action handler. This makes it possible for unauthenticated attackers to execute AJAX actions via a forged… | |
| Modificada | Alta (8.8) | 0.21% | — | Supsystic Contact Form | 12/10/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Supsystic Contact Form by Supsystic plugin <= 1.7.27 versions. | |
| Modificada | Crítica (9.8) | 1.5% | — | Supsystic Popup | 17/7/2023 | 17/6/2026 | The Popup by Supsystic WordPress plugin before 1.10.19 has a prototype pollution vulnerability that could allow an attacker to inject arbitrary properties into Object.prototype. | |
| Modificada | Media (5.4) | 0.28% | — | Supsystic Easy Google Maps | 9/6/2023 | 17/6/2026 | The Easy Google Maps plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.11.7. This is due to missing or incorrect nonce validation on the AJAX action handler. This makes it possible for unauthenticated attackers to executes AJAX actions via a forged request granted… | |
| Modificada | Alta (8.8) | 0.25% | — | Supsystic Easy Google Maps | 28/5/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Supsystic Easy Google Maps plugin <= 1.11.7 versions. | |
| Modificada | Alta (8.8) | 0.27% | — | Supsystic Coming Soon | 22/5/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Supsystic Coming Soon by Supsystic plugin <= 1.7.10 versions. | |
| Modificada | Alta (8.8) | 0.32% | — | Supsystic Contact Form | 17/5/2023 | 17/6/2026 | The Contact Form by Supsystic plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.7.24. This is due to missing or incorrect nonce validation on the AJAX action handler. This makes it possible for unauthenticated attackers to execute AJAX actions via a forged request… | |
| Modificada | Alta (7.2) | 0.70% | — | Apsystems Alternergy Power Control Software | 11/5/2023 | 17/6/2026 | Altenergy Power Control Software C1.2.5 was discovered to contain a remote code execution (RCE) vulnerability via the component /models/management_model.php. | |
| Modificada | Crítica (9.8) | 0.62% | — | Synopsys Code DX | 27/4/2023 | 17/6/2026 | Code Dx versions prior to 2023.4.2 are vulnerable to user impersonation attack where a malicious actor is able to gain access to another user's account by crafting a custom "Remember Me" token. This is possible due to the use of a hard-coded cipher which was used when generating the token. A malicious actor who… | |
| Modificada | Media (5.3) | 0.43% | — | Synopsys Coverity | 29/3/2023 | 17/6/2026 | Coverity versions prior to 2023.3.2 are vulnerable to forced browsing, which exposes authenticated resources to unauthorized actors. The root cause of this vulnerability is an insecurely configured servlet mapping for the underlying Apache Tomcat server. As a result, the downloads directory and its contents are… | |
| Analizada | Crítica (9.8) | 2.7% | ⚠ Explotación activa | Helpsystems Cobalt Strike | 24/3/2023 | 17/6/2026 | Cobalt Strike 4.7.1 fails to properly escape HTML tags when they are displayed on Swing components. By injecting crafted HTML code, it is possible to remotely execute code in the Cobalt Strike UI. | |
| Modificada | Crítica (9.8) | 85% | 💥 Exploit | Apsystems Energy Communication Unit Firmware | 14/3/2023 | 17/6/2026 | OS command injection affects Altenergy Power Control Software C1.2.5 via shell metacharacters in the index.php/management/set_timezone timezone parameter, because of set_timezone in models/management_model.php. | |
| Modificada | Alta (8.8) | 0.28% | — | Supsystic Slider | 14/3/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Supsystic Slider by Supsystic plugin <= 1.8.5 versions. | |
| Modificada | Media (4.3) | 0.51% | — | Jenkins Synopsys Coverity | 15/2/2023 | 17/6/2026 | A missing permission check in Synopsys Jenkins Coverity Plugin 3.0.2 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins. |